BlackBerryForums.com : Your Number One BlackBerry Community
     

»Sponsored Links


BlackBerryApps.com Best Sellers



Reply
 
LinkBack Thread Tools
  (#1 (permalink)) Old
Frikkels Offline
Knows Where the Search Button Is
 
Posts: 19
Join Date: Apr 2009
Model: bold
PIN: N/A
Carrier: Vodacom
Default Blackberry Server and the DMZ!!! - 07-17-2009, 10:18 AM

Hi

We have a Blackberry Server that sends the mail out via our Proxy Server. Our Security team wants to move that to the DMZ Part of our network. What needs to be done for Blackberry to still work. I check some stuff on the web and they talk about a blackberry router that you can put in the dmz, but we dont have one.

Hope i gave enough information.

Thanks
   
Reply With Quote
Sponsored Links
Please Login or Register to Remove these Advertisements!

  (#2 (permalink)) Old
SteveO86 Online
Bay Harbor Butcher
 
SteveO86's Avatar
 
Posts: 5,236
Join Date: Sep 2007
Location: Florida
Model: 9550
OS: 5.0.0.320
PIN: I heard it drop!
Carrier: Verizon Wireless BIS
Default 07-17-2009, 11:42 AM

BlackBerry Router is a Service on the BES, that can be installed on a separate box, inside the DMZ.

I would check the BES documentation for your particular version.


For the first time I feel the future might hold something different for me. It's possible I'm fooling myself but I'm willing to take the risk.

Follow me on Twitter

Blogging at BlackBerryBoardsNews
   
Reply With Quote
  (#3 (permalink)) Old
CanuckBB Offline
CrackBerry Addict
 
CanuckBB's Avatar
 
Posts: 855
Join Date: Feb 2006
Location: YYZ
Model: 8330
OS: 4.5.0.131
Carrier: Bell
Default 07-17-2009, 02:24 PM

You would need a seperate server to in the DMZ to run the BES Router service. You then need open ports for the BES to talk to it's router. That still leaves a way in. If I can get to oyur Router, I could use those open ports to get into your network.

All BES requires is port 3101 OUTBOUND to be open. It's as secure as can be.
   
Reply With Quote
  (#4 (permalink)) Old
Frikkels Offline
Knows Where the Search Button Is
 
Posts: 19
Join Date: Apr 2009
Model: bold
PIN: N/A
Carrier: Vodacom
Default 07-20-2009, 06:09 AM

Hi I found the following Q&A:

Q) can we have the BB server setup in DMZ. If so can someone explain me the advantages and disadvantages?

Thanks,
Sridhar

A) Yes. No point really though since you will have to poke a ton of holes in your firewall.. If you are not hosting MDS applications BES doesn't require any open incoming ports, so again no point... RIM has a lot of documentation about this.

My Q: If there are no open incomming ports, how does the blackberry sync back to the mailbox if you delete mail on the device?

Is it really necesary to have the BB Server in a DMZ??

Thanks,
   
Reply With Quote
  (#5 (permalink)) Old
southwestcomm Offline
BlackBerry Extraordinaire
 
Posts: 1,326
Join Date: Jan 2005
Model: Many
Carrier: Sprint
Default 07-20-2009, 11:14 PM

The BB Router can be installed in the DMZ. All other BES components need to be behind the firewall.

Quote:
Originally Posted by Frikkels View Post
Hi I found the following Q&A:

Q) can we have the BB server setup in DMZ. If so can someone explain me the advantages and disadvantages?

Thanks,
Sridhar

A) Yes. No point really though since you will have to poke a ton of holes in your firewall.. If you are not hosting MDS applications BES doesn't require any open incoming ports, so again no point... RIM has a lot of documentation about this.

My Q: If there are no open incomming ports, how does the blackberry sync back to the mailbox if you delete mail on the device?

Is it really necesary to have the BB Server in a DMZ??

Thanks,
   
Reply With Quote
  (#6 (permalink)) Old
Frikkels Offline
Knows Where the Search Button Is
 
Posts: 19
Join Date: Apr 2009
Model: bold
PIN: N/A
Carrier: Vodacom
Default Bb Router Install after BESX has been implented - 07-21-2009, 07:42 AM

Hi

Can you add a blackberry router to an existing BES setup. Like i said in the first reply: we have an existing BES network all working, but now they want to move it to the DMZ, i read somewhere that you can only add a BB router when you install the Server. is it possible to remove the bb router service from the existing server and move it to a machine (BTW what is the hardware specs for a bb router, i can only find the os requirements) in the dmz and make that the BB router???

Sorry i am new to the BES enviroment

Thanks,
   
Reply With Quote
  (#7 (permalink)) Old
clady Offline
New Member
 
Posts: 4
Join Date: Aug 2009
Model: 8800
PIN: N/A
Carrier: TIM
Default BlackBerry router in DMZ - 08-12-2009, 03:21 AM

Hi Frikkels,

as other told you before, the best thing is to install a BlackBerry router on your DMZ Network. It can be done using the setup file used to install BES Server. At the beginning, there are some installation option, which one of them is the BB Router installation.

Once installed, you don't need to uninstall the local BB Router but you have to configure the BES to forward TCP 3101 traffic to the new BB Router:
from the BES, open BlackBerry Server Configuration and, under Router settings, change the SRP address with the IP address of your BB Router. Leave the other settings (all TCP ports 3101). Obviously, the BB Router has to be configured to point the Internet SRP address (for Italy is the srp.it.blackberry.net).

We have that kind of configuration and I can confirm you that you have to open only the outgoing TCP port 3101:

BES -(TCP 3101)-> BB Router -(TCP 3101)-> Internet RIM SRP

Moreover, BB Router can run with local system account privileges so you can have a standalone machine in DMZ. Otherwise you have also to allow on the firewall all the traffic needed by a member server of an M$ AD Domain (RPC, Kerberos, LDAP and more.................).

Bye.
   
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On





Copyright © 2004-2009 BlackBerryFAQ.com, BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of Research In Motion Limited.